PPA with proposed packages:

https://launchpad.net/~lucaskanashiro/+archive/ubuntu/ha-stack-aws

** Description changed:

+ [Impact]
+ 
+ This update is considered as a hardware enablement feature which will
+ allow AWS users to make use of the IMDSv2 support recently added to
+ fence-agents. This is an important security related feature recently
+ introduced by AWS.
+ 
+ [Test Case]
+ 
+ TBD
+ 
+ [Where problems could occur]
+ 
+ All the patches needed change only the fence_aws.py file, so if a
+ problem could occur it would affect only fence_aws.
+ 
+ [Original Description]
+ 
  Last year, AWS released "IMDSv2" in an effort to protect customers against 
some potentially severe information leaks related to accidentally proxying this 
local data to the network. Details
  at 
https://aws.amazon.com/blogs/security/defense-in-depth-open-firewalls-reverse-proxies-ssrf-vulnerabilities-ec2-instance-metadata-service/
  
  IMDSv2 makes use of a session-based protocol, requiring clients to first
  retrieve a time-limited session token, and then to include that token
  with subsequent requests.
  
  Because the intended purpose of IMDSv2 is to provide an additional layer
  of defense against network abuses, customers utilizing it may choose to
  disable IMDSv1. Disabling IMDSv2 today causes fence_aws to fail.

** Summary changed:

- Backport the fence_aws support for IMDSv2
+ [SRU] Backport the fence_aws support for IMDSv2

** Changed in: fence-agents (Ubuntu Bionic)
       Status: New => In Progress

** Changed in: fence-agents (Ubuntu Focal)
       Status: New => In Progress

** Changed in: fence-agents (Ubuntu Groovy)
       Status: New => In Progress

** Changed in: fence-agents (Ubuntu Bionic)
     Assignee: (unassigned) => Lucas Kanashiro (lucaskanashiro)

** Changed in: fence-agents (Ubuntu Focal)
     Assignee: (unassigned) => Lucas Kanashiro (lucaskanashiro)

** Changed in: fence-agents (Ubuntu Groovy)
     Assignee: (unassigned) => Lucas Kanashiro (lucaskanashiro)

** Changed in: fence-agents (Ubuntu)
     Assignee: (unassigned) => Lucas Kanashiro (lucaskanashiro)

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1915190

Title:
  [SRU] Backport the fence_aws support for IMDSv2

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/fence-agents/+bug/1915190/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to